ZDI-CAN-20554: ZDI-23-632: D-Link DIR-2150 SetTriggerPPPoEValidate Username Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20554?
The severity of ZDI-CAN-20554 is high due to the potential for remote code execution by network-adjacent attackers.
How do I fix ZDI-CAN-20554?
To fix ZDI-CAN-20554, users should update the firmware of their D-Link DIR-2150 routers to the latest version provided by the manufacturer.
What type of attacker can exploit ZDI-CAN-20554?
ZDI-CAN-20554 can be exploited by network-adjacent attackers who can bypass existing authentication mechanisms.
What devices are affected by ZDI-CAN-20554?
The affected device for ZDI-CAN-20554 is the D-Link DIR-2150 router.
Is authentication required to exploit ZDI-CAN-20554?
Yes, authentication is required to exploit ZDI-CAN-20554, but the existing mechanism can be bypassed.